Data Persisting in Models Beyond Retention Limits
保留期限屆滿後仍存於模型
Retirement
Risk Description
When an organization deletes source data as required once the retention period expires, but the existing model continues operating and reflecting that data's characteristics; due to unmitigated control gaps, asked during an audit how it ensures expired data is no longer used, the organization has no workable technical answer, triggering compliance exposure and operational reputational costs.
Framework Mappings
EU AI ActArt.10
NIST AI 600-1Data Privacy
ISO/IEC 42001Annex A.7.2、A.7.6
ISO/IEC 5338退役
MIT AI Risk RepositoryDomain 2
Risk Treatment & Implementation Guidance
Bring models into data lifecycle management so retention policies cover models trained on the data and their derivatives; Before expiry, assess disposition—retraining with exclusion, unlearning, or retirement—and document the rationale; Maintain a data-to-model register so audits can trace which models each batch influenced